What is CVE-2026-72922?
CVE-2026-72922 is a vulnerability in AutoGPT versions prior to 0.6.70, where the `webhook_ingress_generic` route in `router.py` selects `get_webhook_manager` using an untrusted `provider` parameter. This may lead to remote code execution; users should urgently upgrade to version 0.6.70 or later.
Azərbaycanca: CVE-2026-72922 AutoGPT platformasında, 0.6.70 öncəsi versiyalarda `webhook_ingress_generic` route-da etibarsız `provider` parametrinə görə `get_webhook_manager` funksiyasının seçilməsi boşluğudur. Bu, uzaqdan kod icrasına səbəb ola bilər; AutoGPT istifadəçiləri dərhal 0.6.70+ versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which versions of AutoGPT are affected by CVE-2026-72922?
This vulnerability affects all AutoGPT versions prior to 0.6.70. Users must upgrade to version 0.6.70 or later.
What is the potential impact of successfully exploiting CVE-2026-72922?
This vulnerability may lead to remote code execution (RCE) on the AutoGPT platform.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.